| Social Networking Policy |
IT-10-09_Policy_on_Social_Networking.pdf |
ETSS |
2018-02-28 |
This policy is aimed at allowing state agencies and departments the benefit of using social networking for the performance of state business, to communicate with the public, protect the infrastructure and legal interests of the State of Rhode Island and assure that adequate bandwidth is available to conduct State business without interruption |
| State Network Device Security Policy 10-04 |
ETSS_Policy_10-04_State_Network_Device_Security.pdf |
ETSS |
2025-04-20 |
Establish policy and guidance for appropriately managing and securing State Network Devices. Protect employees and the workplace environment through reducing the risk of compromising state data, disruption of network resources, and legal-related issues. The intent of this policy is to maintain the confidentiality and integrity of state data, ensure the availability of network resources, and assist in the reduction of financial and legal penalties associated with non-compliance of federal and state programs. |
| Supply Chain Risk Management Policy |
ETSS_Policy_800.2_Supply_Chain_Risk_Management__SR_.pdf |
ETSS |
2026-07-14 |
This policy establishes the requirements for identifying, assessing, and mitigating risks associated with the information and communications technology (ICT) supply chain. |
| System and Communications Protection Policy |
ETSS_Policy_300.4_System_and_Communications_Protection_.pdf |
ETSS |
2026-07-14 |
This policy establishes the requirements for protecting State of Rhode Island information systems, networks, and communications to ensure the confidentiality, integrity, and availability of information resources. It defines controls for system segmentation, boundary protection, transmission and data-at-rest encryption, cryptographic key management, network session management, DNS security, and other communications protection mechanisms. |
| System and Information Integrity Policy |
ETSS_Policy_300.5_System_and_Information_Integrity__SI_.pdf |
ETSS |
2026-07-14 |
This policy establishes the requirements for maintaining the integrity of State of Rhode Island information systems and data. It defines controls for flaw remediation, malicious code protection, system monitoring, security alerts, software and firmware integrity verification, spam protection, information input validation, error handling, information retention, and memory protection. |
| System and Services Acquisition Policy |
ETSS_Policy__800.1_System_and_Services_Acquisition.pdf |
ETSS |
2026-07-14 |
This policy establishes the requirements for acquiring, developing, and managing information systems and services with adequate security controls to safeguard the State’s information, infrastructure, and data. It defines requirements for resource allocation, system development lifecycle integration, acquisition processes, system documentation, security engineering principles, external system services, developer configuration management and testing, and the management of unsupported system components. |
| System Maintenance Policy |
ETSS_Policy_100.2_System_Maintenance__MA_.pdf |
ETSS |
2026-07-14 |
This policy establishes the requirements for the effective and secure maintenance, repair, and diagnostic servicing of State of Rhode Island information systems and system components. It defines requirements for controlled maintenance activities performed on-site or off-site, the management and inspection of maintenance tools, non-local (remote) maintenance, the authorization of maintenance personnel, and timely maintenance support. |